Community discussions

MikroTik App

Search found 54 matches

by petrushka
Wed Oct 21, 2020 12:19 am
Forum: General
Topic: BUG: (another one) ipsec policy netmask
Replies: 5
Views: 1568

Re: BUG: (another one) ipsec policy netmask

Oh, don't know, just tried to play with some wiki sample

Thank you
by petrushka
Sun Oct 18, 2020 11:43 am
Forum: General
Topic: BUG: (another one) ipsec policy netmask
Replies: 5
Views: 1568

Re: BUG: (another one) ipsec policy netmask

Hi guys, having the same issue with adding this line, it won't accept dst address: /ip ipsec policy add src-address=10.0.35.0/24:any dst-address=10.0.10.0/24:any sa-src-address=10.0.56.30 sa-dst-address=10.0.56.29 tunnel=yes action=encrypt proposal=default invalid value for argument dst-address: val...
by petrushka
Thu Apr 26, 2012 2:40 pm
Forum: Scripting
Topic: help find lease by comment
Replies: 6
Views: 2454

Re: help find lease by comment

so understand, this must be putted in WIKI, in manual API as a restricted substring feature ...
by petrushka
Wed Apr 25, 2012 7:13 am
Forum: Scripting
Topic: help find lease by comment
Replies: 6
Views: 2454

Re: help find lease by comment

Thank you ! skillful You save me a lot of time :)

But it doesn't work thrue PHP API, this ~ must be something different.

/ip/dhcp-server/lease/print
?comment~customer

Not working.
by petrushka
Tue Apr 24, 2012 9:45 pm
Forum: Scripting
Topic: help find lease by comment
Replies: 6
Views: 2454

help find lease by comment

Trying to find by incomplete comment ROS 5.15: ip dhcp-server lease print where comment="customer" but full comment is "customer 0001 blablabla","customer 0002 blablabla", when using command above,- shows nothing. but when comments only such as "0001","00...
by petrushka
Fri Apr 13, 2012 12:20 am
Forum: General
Topic: v5.14 released
Replies: 73
Views: 27146

Re: v5.14 released

now it is ok, just changed again password to what it be :|
by petrushka
Thu Apr 12, 2012 11:56 pm
Forum: General
Topic: v5.14 released
Replies: 73
Views: 27146

Re: v5.14 released

API login failure for user ... 5.14, before update was no problem
by petrushka
Wed Apr 11, 2012 2:02 pm
Forum: General
Topic: Routerboard 433GL slow connection speed
Replies: 11
Views: 3470

Re: Routerboard 433GL slow connection speed

changed my cpu Mhz to 680, it becomes faster, but throughput not more than 30 Mbits
by petrushka
Tue Apr 10, 2012 11:04 am
Forum: General
Topic: Routerboard 433GL slow connection speed
Replies: 11
Views: 3470

Re: Routerboard 433GL slow connection speed

Yes few times was shown to me, firewall eats (and every time profile sends me to a mikrotik support, because can't display something from profile), but if I have 100 Mhz in settings, I thing a fly will eat it too. With my configuration or (not configured), throughput is not above 20 Mbps, and local ...
by petrushka
Tue Apr 10, 2012 9:40 am
Forum: General
Topic: Routerboard 433GL slow connection speed
Replies: 11
Views: 3470

Re: Routerboard 433GL slow connection speed

Mine is too 5.14, but something wrong with it.
take a suppout.rif and send it to MT support@mikrotik.com
maybe they fix this faster... my customer alittle becomes MAD (((
by petrushka
Fri Apr 06, 2012 2:46 pm
Forum: General
Topic: Routerboard 433GL slow connection speed
Replies: 11
Views: 3470

Re: Routerboard 433GL slow connection speed

Looks like it work as ZX Spectrum :) Check your 100MHz cpu :) Seems to be 680.. I need it work on Monday :(
by petrushka
Thu Apr 05, 2012 9:09 pm
Forum: General
Topic: Routerboard 433GL slow connection speed
Replies: 11
Views: 3470

Re: Routerboard 433GL slow connection speed

The same problem too, when Firewall enabled with some charging rules, speed is not more than 13 mb/s. Please help with ..

I need to connect to it about 10 wired, and 5 wireless... If I know about such problems, I'd prefer to bought some buffalo HW.
by petrushka
Tue Mar 06, 2012 11:46 am
Forum: The Dude
Topic: Why i cant ping anyting in my network?! (in Dude 4.0)
Replies: 31
Views: 42803

Re: Why i cant ping anyting in my network?! (in Dude 4.0)

Look at the cstrutt 's comment, it realy work ! c:\Program Files (x86)\Dude\dude.exe), right mouse select Properties click on the Compatibility tab then check the "Run this program as an administrator" Kill service, start again and vuala :) Thanks to cstrutt 's comment, the second day star...
by petrushka
Thu Oct 13, 2011 4:17 pm
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

Dah, it is heavy to understand it
Sure, check screenshots here:
viewtopic.php?p=282910#p282910
from your side, because you have different imagination of task that I can understand :)
I'll try to harder my configuration... Anyway thank you for attention !
by petrushka
Thu Oct 13, 2011 9:18 am
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

Hel, as I understand ... or you can qos packets in global-in (global-in for upload and download) and limit users bandwidth in global-out (global-out for download and upload), just make sure you mangle packets accordingly. I need for services prerouting mangle rules with src=>dst=download and dst=>sr...
by petrushka
Wed Oct 12, 2011 7:19 pm
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

Hel

It means, that I need to catch download traffic only from local interfaces (eth1,eth2,eth3,vl2,vl4,vl8), and upload from wan interfaces (wan1,bgp1,bgp2)???
by petrushka
Wed Oct 12, 2011 5:20 pm
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

here is my config, no nat QOS priority for services is working fine in both way. Shaper Users download is working too, Shaper Users upload does nothing, takes all bainwidth. ::services:: /queue tree add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 \ max-limit=0 name=ensign_se...
by petrushka
Tue Oct 11, 2011 10:11 pm
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

Can please anyone help to understand how to catch traffic on Mangle marked customers (forward) between global in (prerouting) and global out (postrouting) marked services ... ???
by petrushka
Tue Oct 11, 2011 3:54 am
Forum: General
Topic: Double marking and duo Queue tree, which interfaces?
Replies: 29
Views: 6763

Re: Double marking and duo Queue tree, which interfaces?

So great discussion you have.. but serious, do somebody find out how ?? and where to setup correctly? I only find if I marking postrouting to global out, my interface queues for customers are empty. /queue tree add burst-limit=0 burst-threshold=0 burst-time=0s disabled=yes limit-at=0 \ max-limit=0 n...
by petrushka
Thu Oct 06, 2011 10:54 pm
Forum: General
Topic: RB433AH Can't connect to printers trough HotSpot system
Replies: 5
Views: 2146

Re: RB433AH Can't connect to printers trough HotSpot system

Thank you for the answer, just turned off default forward, and put my MAC (printer MAC) to an access list forward = yes, auth = no. So it will be great if it works :) Can't test it at the moment :|
by petrushka
Fri Sep 30, 2011 12:10 pm
Forum: General
Topic: RB433AH Can't connect to printers trough HotSpot system
Replies: 5
Views: 2146

Re: RB433AH Can't connect to printers trough HotSpot system

Normis, please give some example
by petrushka
Fri Sep 30, 2011 12:07 pm
Forum: General
Topic: RB433AH Can't connect to printers trough HotSpot system
Replies: 5
Views: 2146

Re: RB433AH Can't connect to printers trough HotSpot system

Solved, it's not good, but I turned on :

interface wireless set wlan1 default-forward=enable
by petrushka
Fri Sep 30, 2011 11:11 am
Forum: General
Topic: RB433AH Can't connect to printers trough HotSpot system
Replies: 5
Views: 2146

RB433AH Can't connect to printers trough HotSpot system

Good day!

Using RB433AH, hotspot, all working - except can't connect to wireless printers.

even I added them to ip-bindings, walled garden...
by petrushka
Thu Sep 15, 2011 4:19 pm
Forum: Scripting
Topic: automatic clear of status busy in dhcp server
Replies: 8
Views: 10620

Re: automatic clear of status busy in dhcp server

Thanks !!! Script works perfect! :foreach i in=[/ip dhcp-server lease find status="busy"]\ do={ :log error ("Busy status detected: " . [/ip dhcp-server lease get $i address]); /ip dhcp-server lease check-status $i; /ip dhcp-server lease disable $i; /ip dhcp-server lease enable $i...
by petrushka
Wed Aug 31, 2011 12:29 pm
Forum: General
Topic: RouterOS 5.6x86 rx errors tx errors rx drops tx drops
Replies: 4
Views: 3730

Re: RouterOS 5.6x86 rx errors tx errors rx drops tx drops

Good day ! I increased MTU size on RouterOS till 9216 on ethernet which belongs to 400 VLAN 1500 MTU, because on other side it connected to a programmable Switch where programmed Giga Ethernet 9216 MTU,and VLAN 400 - 1500 MTU.. Seems to ERROR drops not happened anymore, but ROS eating alittle bit mo...
by petrushka
Tue Aug 30, 2011 3:42 pm
Forum: General
Topic: RouterOS 5.6x86 rx errors tx errors rx drops tx drops
Replies: 4
Views: 3730

Re: RouterOS 5.6x86 rx errors tx errors rx drops tx drops

I tried to move 400 vlan on a different interface ~ 4eth,- seems to rx errors coming from it, but all the options is the same on both 500 and 400 VLAN's... How can I catch those packets ??
by petrushka
Tue Aug 30, 2011 1:10 pm
Forum: General
Topic: RouterOS 5.6x86 rx errors tx errors rx drops tx drops
Replies: 4
Views: 3730

Re: RouterOS 5.6x86 rx errors tx errors rx drops tx drops

Good day alexspils!

It is the same as Ethernet MTU ( 1500 )
by petrushka
Tue Aug 30, 2011 12:48 pm
Forum: General
Topic: RouterOS 5.6x86 rx errors tx errors rx drops tx drops
Replies: 4
Views: 3730

RouterOS 5.6x86 rx errors tx errors rx drops tx drops

Please help me to analyse what happens with packets that are received with errors. How and where I can collect them to analyse??? And also wants to see what happens with dropped ones.. Tried to use internal logging, but there is hothing about error and drop.. Packet errors happens when it wish, so I...
by petrushka
Thu Mar 24, 2011 10:38 am
Forum: General
Topic: uTorrent real problem QOS, help
Replies: 5
Views: 1696

Re: uTorrent real problem QOS, help

Oh I'm stupid monkey ... Offcourse!! I found it :)

A little cup of knowledge, comes with a huge part of time.

Thank you Normis, My eyes are watching better !
by petrushka
Wed Mar 23, 2011 1:42 pm
Forum: General
Topic: uTorrent real problem QOS, help
Replies: 5
Views: 1696

Re: uTorrent real problem QOS, help

http://wiki.mikrotik.com/wiki/File:IP_final.png So to mark INCOMMING traffic I need to use PREROUTING mangle and the GLOBAL-IN queues to mark OUTGOING traffic I need to use POSTROUTING mangle and the GLOBAL-OUT queues ? I'am right ?? But if I had 1 BGP and 2 BGP peer, where to catch INC and OUT traf...
by petrushka
Wed Mar 23, 2011 12:53 pm
Forum: General
Topic: uTorrent real problem QOS, help
Replies: 5
Views: 1696

Re: uTorrent real problem QOS, help

Is there a difference where to catch MARK traffic ??? (prerouting, postrouting, forward) ??? As I saw not all traffic goes on a prerouting chain.. where to effective catch it ??
by petrushka
Tue Mar 22, 2011 10:43 pm
Forum: General
Topic: uTorrent real problem QOS, help
Replies: 5
Views: 1696

uTorrent real problem QOS, help

Can anybody find how to priorityse the uTorrent traffic ?!??? I'm using example by Janis Megis (http://wiki.mikrotik.com/images/8/8d/QoS_Megis_%28Russian_translate_by_white_crow_rev.2%29.pdf), BUT 'Other' type of packets is MORE than known in mangle: /ip firewall mangle add action=mark-packet chain=...
by petrushka
Tue Feb 22, 2011 7:02 pm
Forum: General
Topic: Queues
Replies: 1
Views: 649

Re: Queues

Try to use Mark rules by time to a specific marks, then pick them in queue tree. /ip firewall mangle add action=mark-connection chain=forward comment=all_traffic disabled=no \ new-connection-mark=traffic_conn passthrough=yes src-address-list=ppoe add action=mark-packet chain=forward connection-mark=...
by petrushka
Wed Oct 27, 2010 6:00 pm
Forum: General
Topic: Ros 5.0rc2 x86 Rx Drops
Replies: 2
Views: 1591

Re: Ros 5.0rc2 x86 Rx Drops

nope, I'm not using OSFP and BGP... :(
by petrushka
Wed Oct 27, 2010 4:01 pm
Forum: General
Topic: Ros 5.0rc2 x86 Rx Drops
Replies: 2
Views: 1591

Ros 5.0rc2 x86 Rx Drops

packet_drop.JPG Good day, Help me please to discover the problem, is that comes because I using simple queues ?? As I understand Rx Drops happens when the: Queue rate is reached it's MAXimum possibility to transfer packets. Or it is simply the NIC's limitation ??? Can't imagine, CPU 4 cores isn't p...
by petrushka
Tue Aug 17, 2010 3:45 pm
Forum: General
Topic: Mikrotik bainwidth rate reservation
Replies: 3
Views: 924

Re: Mikrotik bainwidth rate reservation

Thanks will try,
But as I understand it affects to all users in networks ?
Or I can do this only for those IP's which I mark example PC1 = pcq download/upload, PC2 = pcq down/upl?
by petrushka
Mon Aug 16, 2010 3:10 pm
Forum: General
Topic: Mikrotik bainwidth rate reservation
Replies: 3
Views: 924

Mikrotik bainwidth rate reservation

I need some adwise, in how to realize this scheme. All traffic is aprox 300 Mb/ps, need a rule, in which I can put some IP addreses , to reserv them about 2 mb/ps, so they allways has 2 mb/ps; but if traffic is healthy, they use more than 2 mb/ps but not less than 2 mb/ps. What kind of features used...
by petrushka
Fri Aug 13, 2010 1:17 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

I found the way ! Thanks to this article http://www.mikrotik.com/testdocs/ros/3.0/pnp/proxy.php chain=dstnat action=redirect to-ports=8080 protocol=tcp src-address-list=gues_who dst-address-list=!local-addr in-interface=!Public dst-port=80 I created rule that collects all of these non known IP's, ;;...
by petrushka
Thu Aug 12, 2010 3:29 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

I think I need this rule, because Utorr uses src port 80 = to dst (UPORT)
chain=dstnat action=redirect to-ports=8080 protocol=tcp
src-address-list=!known_users in-interface=!Public src-port=!80
dst-port=80 connection-mark=http
by petrushka
Thu Aug 12, 2010 11:05 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

it is impossible to spit all traffic, Utorrents distributing their user lists thrue 80 port :( maybe I need to use l7 features ?
by petrushka
Wed Aug 11, 2010 2:09 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Site is realy on the second router, but, can't understand why torrents redirects there ?!
I imagine real DOS attack to my web :D it was down twice today :(
by petrushka
Wed Aug 11, 2010 2:02 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Yes, all subnets are static, and all with real DHCP IP addrs.
by petrushka
Wed Aug 11, 2010 1:56 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

now it still MY_PUB_IP- - [11/Aug/2010:01:46:37 +0300] "GET /lv_LV/reminder.html HTTP/1.1" 200 12771 "-" "uTorrent/2020(19648)" MY_PUB_IP - - [11/Aug/2010:01:46:34 +0300] "GET /lv_LV/reminder.html HTTP/1.1" 200 12771 "-" "uTorrent/2020(19648)&qu...
by petrushka
Wed Aug 11, 2010 1:47 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

/ip firewall filter add action=accept chain=input comment="Allow limited pings" disabled=no \ limit=50/5s,2 protocol=icmp add action=log chain=input disabled=yes log-prefix=PINGS protocol=icmp add action=drop chain=input comment="Drop excess pings" disabled=no protocol=\ icmp add...
by petrushka
Wed Aug 11, 2010 1:31 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Now chain contains : I will check it ! chain=dstnat action=redirect to-ports=8080 protocol=tcp src-address-list=!known_users in-interface=!public dst-port=80 connection-mark=http But I think I need to restrict forward rules, I don't need to traffic comes from outside Public. In access log on webserv...
by petrushka
Wed Aug 11, 2010 1:15 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

there is another problem, it redirects Also torrents, and different type of traffic :( most interesting, from outside the router
by petrushka
Tue Aug 03, 2010 5:31 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Good day,
All works perfect !!! Thanks for the helping
by petrushka
Tue Aug 03, 2010 12:50 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

anyway Thank you ! Tomorrow I will change those ISP MTA'S, I hope Mikrotik will be the best :)
by petrushka
Mon Aug 02, 2010 8:35 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

"to pass them thrue" I mean, just as you say - dynamic ARP table.
by petrushka
Mon Aug 02, 2010 8:28 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

hmm, so I need to pass them thrue, add to list "specified" for looking homepage, and do 1-2-3-steps ? I'm sory for the stupid questions, alittle can't understand the policy (as I think it is inverted than in linux iptables :))
by petrushka
Mon Aug 02, 2010 8:11 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

It is so logic ! Thank you for help ! Also I have a 3 DHCP subnets on LAN1 LAN2 LAN3, working with arp reply only, how can I redirect all other users, who have a problems, or not have a static entry - to my web page local? 1. I need to create 3-rd address list which contains all exepted adresses 2. ...
by petrushka
Mon Aug 02, 2010 7:51 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Yes you right, all local services are permitted to time_restricted users. I allready have a rules : add action=accept chain=forward comment="Allow traffic between clients" \ disabled=no in-interface=LAN1 out-interface=LAN1 add action=accept chain=forward comment="Allow traffic between...
by petrushka
Mon Aug 02, 2010 7:42 pm
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

Re: internet restriction from time A till time B

Web page and FTP is internal address space. So as I understand, to filter traffic only for users in adress list I need to do : /ip firewall address-list add address=10.10.10.x list=time_restricted - Users whom need to be restricted /ip firewall address-list add address=10.10.10.x1 list=local-addr - ...
by petrushka
Mon Aug 02, 2010 12:32 am
Forum: Scripting
Topic: internet restriction from time A till time B
Replies: 26
Views: 5217

internet restriction from time A till time B

Can you advice please in how-to realize the time restriction on MTA. I have an NTP time server and Client, address list, predefined rule in firewall (which allows only internal ftp and homepage conection). I need to enable at 18:00 and disable at 08:00 this rule in scheduler, to restrict access outs...